Home · Solutions · HR & people

Solution · HR & people

Accounts, roles and equipment ready before day one, and switched off the day someone leaves

Joiner, mover, leaver: access on day one, revoked same day

One HR event provisions every account, licence, group, system role and piece of equipment, and the same pipeline revokes all of it on the leaving date, with evidence.

EnterpriseMicrosoft TeamsHuman in the loopDeterministic automation
240joiner, mover and leaver events a month run through four separate checklists in this illustrative retail group, and none of them talk to each other.

Executive summary

Challenge

New starters wait days for access; leavers keep theirs for weeks. Both are the same missing handover.

What changes

The design rests on one principle: employment is declared in exactly one place and everything else reacts to it.

Business value

People work on day one.

Systems involved

Microsoft Entra ID and Microsoft 365; SAP S/4HANA users and roles; warehouse and till applications

Business problem

Employee lifecycle

Three events run the working life of every employee: they join, they move, they leave. Each sets off work in ten to fifteen systems, and each system has a different owner, request channel and definition of done. HR owns the contract, IT owns the directory, the manager owns whether the person can do the job on Monday, facilities owns the badge. Nobody owns the sequence, which is what breaks.

Joiners are the visible failure. Someone who cannot work on day one is paid anyway, so is the colleague covering, and in a store the lost day is a shift on the roster. Managers compensate with a private checklist and a lot of chasing.

Movers are the quiet failure: new access is urgent, old access is nobody's ticket, and entitlements accumulate until the most experienced people hold the combined rights of every job they have held. Leavers are the expensive one. Notice travels through payroll on its own schedule, so a departed employee keeps a working VPN profile, an SAP user and a licence for weeks, and nobody can show an auditor when anything was switched off.

How it works today

A form emailed by HR is the only thing tying the steps below together, at most large employers, whatever the HR system.

  1. PersonHR records the hire, transfer or termination and emails a form to the service desk and to facilities
  2. WaitingThe request queues behind incident work; accounts appear a day or two before the start date, sometimes after it
  3. PersonAn agent creates the identity, assigns the licence and copies group membership from a colleague who "does something similar"
  4. SystemSAP roles, the warehouse application, the till account, VPN and telephony are separate tickets with separate approvers
  5. PersonThe manager keeps a private checklist and chases whatever is missing by day three
  6. Risk of errorInternal moves add new rights and leave the old ones in place, so entitlements grow with every job change
  7. Risk of errorLeavers are disabled when the message gets through; VPN, SAP and smaller applications survive until the next access review
  8. WaitingEquipment and badges are ordered by email, without a due date
PersonWaitingSystemRisk of error

Why the current process costs more than it appears

The cost grows where nobody is looking.

  • Coordination is the real work, not the clicking. Every event touches HR, the service desk, the manager and facilities, and the hours spent chasing between them never become a ticket.
  • Unrevoked accounts are billed twice: as a licence you keep paying for, and as access that should not exist. Neither surfaces until the annual true-up or a penetration test.
  • Accumulated entitlements erode control silently. The finding lands at the audit, months after the combination became possible, and remediation costs far more than removal.
  • Managers rebuild the same knowledge on every hire. What a store systems analyst needs sits in one person's sent items, not in a definition the company can reuse.
  • Answering "does this person still have access to SAP?" takes three teams and a day, which turns every audit sample into an investigation.

Cost of inaction

Twelve months of joiners, movers and leavers coordinated by hand≈ €216,000
The same handover through three more hiring cycles≈ €648,000
At 300 events a month once the next stores open≈ €270,000

Hours are the cheap part of this problem. What compounds is entitlement drift: every move that adds rights without removing any takes the company further from the access picture it believes it has, and the correction is an access-review project rather than a click. Each leaver whose VPN outlives their employment is an open question that becomes expensive on the day someone asks it.

There is also a hiring cost that never appears as one. When day one reliably means day three, induction is improvised and the new employee's first impression is a service-desk queue, formed roughly 110 times a month at 22% turnover.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A retail and logistics group, 6,500 employees across stores, distribution centres and a head office in four countries; SAP SuccessFactors as the HR system of record, SAP S/4HANA in finance, Microsoft 365 with Microsoft Entra ID for the office and management population.

Volume

240 joiner, mover and leaver events a month at 22% annual turnover, roughly 110 joiners, 70 internal moves and 60 leavers, touching fourteen systems and four badge estates.

Current process

Forms travel from HR into a service-desk queue; identities and licences are set up by hand, SAP roles and VPN in separate tickets, equipment and badges by email, and every manager runs a personal checklist.

Bottleneck

About two and a half hours of coordination per event across the four teams, plus a revocation step that depends on someone remembering on the right day.

Solution

The HR record becomes the only trigger. Microsoft Entra ID Governance lifecycle workflows handle the Microsoft 365 identity, UiPath robots handle every system without a connector, the manager gets one checklist in Microsoft Teams, and the leaving date runs a revocation sequence that writes its own evidence.

Potential outcome

In the modelled case, 600 hours a month of coordination are released, joiners start with working access on the start date, and revocation moves from "when someone remembers" to the date in the HR record. The figures are a model, not a measurement.

Proposed solution

The design rests on one principle: employment is declared in exactly one place and everything else reacts to it. A hire, transfer or termination in the HR system is the only event that starts work. No starter form, no parallel spreadsheet, no second definition of a start date, which is also what makes the process auditable.

The Microsoft 365 half is native. Microsoft Entra ID Governance lifecycle workflows run joiner, mover and leaver templates from attribute triggers in the HR data: create the identity, issue a Temporary Access Pass, assign licences and group and Teams membership, and on the leaving date remove licences, strip membership and disable the account. This requires a Microsoft Entra ID Governance or Microsoft Entra Suite licence for every user in scope, which is a real cost line and belongs in the business case rather than a footnote.

Everything else is ours. Most companies run a dozen systems with no lifecycle connector: SAP users and roles, the warehouse application, the till estate, VPN, telephony, badges, procurement. UiPath robots do that work deterministically from the same access profile, called through an Azure Logic Apps task extension, while UiPath Maestro keeps one case per person and event, so a Monday starter is a single object with deadlines rather than eleven tickets. The manager sees one checklist in their Teams channel; anything outside the profile becomes an approval to the system owner.

Native capabilities used

Microsoft Entra ID Governance lifecycle workflows (joiner, mover and leaver templates, attribute triggers, Temporary Access Pass, group and Teams membership, licence removal, account disable); Azure Logic Apps custom task extensions; Microsoft Teams Approvals app; Microsoft Planner tasks through Microsoft Graph; UiPath Orchestrator queues, credential stores and audit

What we build

The access profile catalogue mapping job families to entitlements, the Maestro case that carries each event end to end, the robots for every non-integrated system, the manager checklist and its escalations, the leaving-day revocation sequence with its evidence pack, and the monthly reconciliation

Custom integration

SAP user and role administration through UiPath SAP activities and connectors; VPN, warehouse and till systems through their own interfaces, or their user interface where none exists; badge and equipment requests into facilities and procurement

How the automated process works

  1. AutomationA hire, transfer or termination in SAP SuccessFactors fires an attribute trigger; Maestro opens one case with the start or leaving date as its deadline
  2. AutomationThe lifecycle workflow runs the Microsoft 365 part on the start date: identity, Temporary Access Pass, licences, groups, Teams membership, welcome sequence
  3. SystemRobots provision every system without a connector from the same profile: SAP roles, warehouse and till accounts, VPN, telephony, shared drives, each with its own retry
  4. AutomationEquipment and badge requests go to procurement and facilities with the cost centre from the HR record; confirmed dates return into the case
  5. PersonThe manager gets one Microsoft Planner checklist in Teams: buddy, first-week plan, safety briefing, sign-in confirmed; overdue items escalate
  6. PersonAccess beyond the profile, and leaving-date exceptions, are approvals in Microsoft Teams to the system owner
  7. AutomationOn the leaving date the sequence disables sign-in, strips group and role membership, reclaims the licence, converts the mailbox, locks the SAP user, revokes the VPN certificate and books the badge and laptop return, one timestamped record per step
  8. AutomationMonthly, the pipeline compares HR records against Microsoft Entra ID, SAP users and the other systems, and reports every identity with no employment record
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Provisioning timed to the start date, and removal timed to the leaving date
  • System access derived from job data in the HR record: position, department, location, cost centre
  • Equipment orders, badge requests and return bookings, with the cost centre from the record
  • The evidence: what was granted, under which rule, who approved exceptions, when each revocation completed

People decide

  • Access beyond the profile, approved in Teams by the system owner within their delegated authority
  • Whether a mover keeps anything from the previous role, and for how many days
  • Leaving-date exceptions: a restricted notice period, garden leave, a dispute, a rehire
  • The access profile catalogue, owned by the business rather than by the service desk

Before and after

BeforeAfter
Coordination effort per eventabout 150 min across four teamsminutes of review, on exceptions
New starter able to workday two to day fouron the start date
Termination record to last access revokeddays or weeksthe leaving date, with a timestamp
Rights left behind after an internal moveusually keptremoved with the previous profile
Identities with no employment recordfound at the auditlisted and cleared every month

Systems and integrations

Everything below runs on licences and systems you already hold, or would need anyway.

Inputs

  • SAP SuccessFactors hire, transfer and termination records
  • the access profile catalogue
  • manager and cost-centre data
  • the equipment standard

Automation layer

  • Entra ID Governance lifecycle workflows
  • Azure Logic Apps
  • UiPath Maestro
  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Action Center

Target systems

  • Microsoft Entra ID and Microsoft 365
  • SAP S/4HANA users and roles
  • warehouse and till applications
  • VPN and telephony
  • badges
  • procurement

Human touchpoints: Teams Approvals for out-of-profile access; the manager's Planner checklist; Action Center exception tasks

SAP SuccessFactors hireEntra ID Governance lifecycle workflowsAzure Logic AppsMicrosoft Entra IDTeams Approvals for out-of-profile access

Technologies used

Microsoft Entra ID Governance (lifecycle workflows)

account, Temporary Access Pass, licences, groups, Teams membership, disable and delete

A
Azure Logic Apps

custom task extensions called from the lifecycle workflow, and the hand-off into UiPath

A
UiPath Robots + Orchestrator

provisioning and revocation in SAP, warehouse, till, VPN, telephony, badge and procurement systems; queues, credentials, audit

A
UiPath Maestro

one long-running case per person and event: sequence, waits, deadlines, escalations

A
UiPath Action Center in Microsoft Teams

approvals and exception tasks completed without leaving Teams

A
Microsoft Teams and Microsoft Planner

the manager's day-one checklist and its due dates

A
SAP SuccessFactors and SAP S/4HANA

the employment record that triggers everything; SAP user and role administration

A
UiPath Insights

provisioning lead time, revocation timeliness and exception volumes

A
Averified product capability (vendor documentation)

Illustrative economic model

A model, not a promise.

Illustrative model
240 lifecycle events a month × 150 minutes of coordination= 600 h / month
600 h × €30 blended fully loaded hourly cost= €18,000 / month
× 12 months= €216,000 / year
Annual coordination effort released (illustrative)≈ €216,000

Treat the 150 minutes as a placeholder you can replace: it is the coordination effort for a whole event across HR, the service desk, the line manager and facilities, including chasing and rework, and it is an illustrative figure from typical ranges, not a measurement at a client. €30 is a blended fully loaded hourly cost for those roles in Central Europe. The result is capacity released, not a headcount reduction.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • People work on day one. Access exists before the person arrives, so the first day is induction, not a service-desk queue.
  • The leaving date means something. Sign-in, VPN, SAP and the smaller applications end on the date in the HR record, with proof of the hour.
  • Internal moves stop adding rights: a transfer removes the previous profile as deliberately as it grants the new one.
  • Licences follow real headcount, reclaimed on the leaving date rather than at the annual true-up.
  • Managers run one checklist in Teams instead of four channels, and see only what needs a human.
  • Hiring peaks need no extra service-desk capacity: a store opening runs through the same pipeline as a single hire.

The management view

  • The lifecycle becomes a service with a lead time, a completion rate and a visible queue, not an assumption that IT will manage.
  • Access is defined once per job and reviewed by the system owners, so a new country or store reuses definitions.
  • Evidence for auditors is produced by the process in the moment, not assembled by hand before a review.
  • The company can answer on any day who has access to what, and prove that the people who left do not.

Board-level KPIs

joiners provisioned on the start datehours from termination to last access revokedidentities with no employment recordout-of-profile approvals per monthlicences reclaimed in the leaving month

Security and governance

An auditor should be able to reconstruct every decision.

  • Each robot holds its own named account per system with only the rights that step needs; secrets stay in the platform credential store or your enterprise vault, never in a script
  • Every grant and revocation writes an immutable line: the rule behind it, the approver of any exception, the system touched and the time it completed, which turns offboarding into evidence rather than assertion
  • Identity and employment data stays in your Microsoft 365 tenant and HR system; orchestration runs in the UiPath Automation Cloud EU region
  • Segregation of duties is enforced by the flow: the requester of out-of-profile access is never its approver
  • Privileged roles are excluded from automatic assignment; they follow the approval path under Microsoft Entra Privileged Identity Management

Why now

01

EU cybersecurity law treats this as a baseline duty: Article 21(2) of Directive (EU) 2022/2555 lists human resources security, access control policies and asset management among the minimum risk-management measures, and supervisors ask for evidence rather than intention

02

Turnover in retail and logistics makes the lifecycle a production line, not an occasional event; in the modelled group it runs at €18,000 a month before anyone counts a licence

03

The Microsoft 365 half is configuration rather than development: lifecycle workflows cover joiner, mover and leaver natively and call Azure Logic Apps for the rest, so custom code is confined to systems with no interface

Relevant executive roles

CHRO

The HR record starts and ends employment everywhere, so HR stops being the place managers chase for IT

CIO

One provisioning path with a full audit trail replaces a dozen ticket queues and copied memberships

CFO

Licences and equipment follow real headcount, and a cost never on a budget line becomes visible

COO

A store opening or a seasonal intake is staffed without the service desk becoming the constraint

Common questions and objections

Our HR data is not clean enough to drive access.

Then the reconciliation is the first deliverable, because it shows exactly which records and which identities disagree. Groups typically find a few hundred mismatches in month one and a handful by month three; the data improves because something finally depends on it.

We already have a service-desk workflow for onboarding.

A ticket workflow tells a person what to do next; this does the work and proves it was done. The service desk keeps the exceptions, which is where their judgement is worth paying for.

Does this mean buying Entra ID Governance?

Lifecycle workflows require Microsoft Entra ID Governance or Microsoft Entra Suite, licensed for every user in scope, and that belongs in the business case openly. Where the licence is not justified, the same sequence can run from UiPath against Microsoft Graph: less native tooling, more that we build.

When this is not the right solution

  • Fewer than roughly thirty lifecycle events a month, where one clear owner and a good checklist beat a provisioning platform
  • The HR system is not the record of hires and terminations, or the record appears after the start date; fix that at the source first
  • Access cannot be described by job. If entitlements are negotiated person by person, the first project is an access review and a role model

A question for the next management meeting

If we ended an employment record this afternoon, how many hours would pass before every account, role and key belonging to that person stopped working, and could we prove it?

Implementation approach

The first week looks the same at every client: we look at the data.

We deliver

  • The access profile catalogue: job families mapped to Microsoft 365 groups, SAP roles, system accounts, VPN profiles and the equipment standard
  • Configuration of Entra ID Governance lifecycle workflows for joiner, mover and leaver, with the Temporary Access Pass and the timing rules
  • Azure Logic Apps task extensions and the hand-off into UiPath for systems with no lifecycle connector
  • Robots for SAP users and roles, warehouse and till systems, VPN, telephony, badges, equipment orders
  • The Maestro case per person and event, with deadlines, escalations and the manager checklist
  • The leaving-day revocation sequence with its evidence pack, and the monthly reconciliation
  • Pilot on one country, then rollout with hypercare and a runbook for the service desk

We need from you

  • The HR data model: which fields declare a hire, a transfer and a termination, and how early they are reliable
  • System owners who can agree what each job family should have, and what it should not
  • Technical accounts in SAP, warehouse and till systems, VPN, telephony, facilities, procurement
  • Your licensing position for Microsoft Entra ID Governance or Microsoft Entra Suite

Stages

Discovery

Event types, systems, existing checklists and the real lead times per country

Role design

Job families mapped to access profiles, approval owners, out-of-profile rules

Build

Lifecycle workflows, Logic Apps extensions, robots, the Maestro case, Teams touchpoints

Validation

Dry runs on historical joiners, movers and leavers; revocation tested against your evidence needs

Go-live

One country first, with the manual checklist alongside until the numbers agree

Optimisation

Reconciliation findings feed the profile catalogue; further systems join the pattern

Enterprise. Effort is driven by the number of target systems without a connector, how many job families need distinct profiles, and the quality of the HR data.